CVE-2021-3420 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.
Group Package Affected Fixed Severity Status Ticket
AVG-1628 riscv32-elf-newlib 3.3.0-2 Medium Vulnerable FS#70050
References
https://bugzilla.redhat.com/show_bug.cgi?id=1934088
https://sourceware.org/git/?p=newlib-cygwin.git;a=commitdiff;h=aa106b29a6a8a1b0df9e334704292cbc32f2d44e